Preview ssh as the derived filter admits it, and say a narrowing to the private network closes (hq ADR 0100)
This commit is contained in:
@@ -217,7 +217,9 @@ func converge(ctx context.Context, open *stores, node string, yes bool, filter s
|
||||
if err != nil {
|
||||
return "", err
|
||||
}
|
||||
preview := previewOf(node, reported, rules, with.Foundation, plan, taken, filter, runs[filter])
|
||||
derived := derivedFilter{rules: rules, foundation: with.Foundation, mesh: with.Mesh,
|
||||
outward: plan.PublicDomain != ""}
|
||||
preview := previewOf(node, reported, derived, plan, taken, filter, runs[filter])
|
||||
if !yes {
|
||||
return preview + fmt.Sprintf("\n\nNothing has changed. Run `converge %s --yes` to do it.", node), nil
|
||||
}
|
||||
@@ -252,7 +254,7 @@ func converge(ctx context.Context, open *stores, node string, yes bool, filter s
|
||||
}
|
||||
|
||||
// previewOf is what converging a node will change, before it changes it.
|
||||
func previewOf(node string, reported inventory.Adoption, rules []catalogue.Rule, foundation []int,
|
||||
func previewOf(node string, reported inventory.Adoption, derived derivedFilter,
|
||||
plan catalogue.Resolution, taken []string, filter string, filterAssigned bool) string {
|
||||
var b strings.Builder
|
||||
fmt.Fprintf(&b, "converging %s\n", node)
|
||||
@@ -269,7 +271,7 @@ func previewOf(node string, reported inventory.Adoption, rules []catalogue.Rule,
|
||||
if r.Published {
|
||||
what += fmt.Sprintf(" (published, container port %d)", r.ContainerPort)
|
||||
}
|
||||
fmt.Fprintf(&b, " %-44s %s\n", what, fate(r, rules, foundation))
|
||||
fmt.Fprintf(&b, " %-44s %s\n", what, derived.fate(r))
|
||||
}
|
||||
if len(reported.Reachable) == 0 {
|
||||
b.WriteString(" nothing reported\n")
|
||||
@@ -317,26 +319,56 @@ func previewOf(node string, reported inventory.Adoption, rules []catalogue.Rule,
|
||||
return strings.TrimRight(b.String(), "\n")
|
||||
}
|
||||
|
||||
// derivedFilter is what the filter the flip loads is rendered from, as AsNftables renders it.
|
||||
type derivedFilter struct {
|
||||
rules []catalogue.Rule
|
||||
foundation []int
|
||||
// mesh is every address on the private network; outward says the machine faces outside.
|
||||
mesh []string
|
||||
outward bool
|
||||
}
|
||||
|
||||
// closesOutside is what a narrowing from everywhere to the private network is called: it closes.
|
||||
const closesOutside = "WILL CLOSE to everything outside the private network"
|
||||
|
||||
// fate is what the derived filter does to one reachable thing: which module declares it and from
|
||||
// where, or that it will close.
|
||||
func fate(r inventory.Reach, rules []catalogue.Rule, foundation []int) string {
|
||||
// where, or that it will close — wholly, or to everything outside the private network. Rendered
|
||||
// exactly as AsNftables admits it, ssh included.
|
||||
func (d derivedFilter) fate(r inventory.Reach) string {
|
||||
// Bound to an address on the private network, it was never reachable from outside it, so
|
||||
// admitting it from the mesh narrows nothing.
|
||||
onMesh := slices.Contains(d.mesh, strings.Trim(r.Address, "[]"))
|
||||
if r.Protocol == "tcp" && r.Port == catalogue.SSHPort {
|
||||
return "stays open — ssh is never closed"
|
||||
// From everywhere only when the machine faces outward or the mesh has no addresses to
|
||||
// narrow it to; otherwise from the private network only.
|
||||
if d.outward || len(d.mesh) == 0 || onMesh {
|
||||
return "stays open — ssh is never closed"
|
||||
}
|
||||
return closesOutside + " — ssh stays open from the mesh, never closed there"
|
||||
}
|
||||
for _, port := range foundation {
|
||||
for _, port := range d.foundation {
|
||||
if r.Protocol == "tcp" && r.Port == port {
|
||||
return "stays open — the mesh's own, from anywhere"
|
||||
}
|
||||
}
|
||||
for _, rule := range rules {
|
||||
for _, rule := range d.rules {
|
||||
if rule.Port != r.Port || rule.Protocol != r.Protocol {
|
||||
continue
|
||||
}
|
||||
if rule.From == catalogue.FromMachine {
|
||||
return fmt.Sprintf("WILL CLOSE to the network — declared by %s for this machine only",
|
||||
strings.Join(rule.Because, ", "))
|
||||
by := strings.Join(rule.Because, ", ")
|
||||
switch rule.From {
|
||||
case catalogue.FromMachine:
|
||||
return fmt.Sprintf("WILL CLOSE to the network — declared by %s for this machine only", by)
|
||||
case catalogue.FromMesh:
|
||||
if len(d.mesh) == 0 {
|
||||
return fmt.Sprintf("WILL CLOSE — declared by %s from the mesh, and this node "+
|
||||
"knows no mesh addresses", by)
|
||||
}
|
||||
if !onMesh {
|
||||
return fmt.Sprintf("%s — declared by %s from the mesh only", closesOutside, by)
|
||||
}
|
||||
}
|
||||
return fmt.Sprintf("declared by %s (from %s)", strings.Join(rule.Because, ", "), rule.From)
|
||||
return fmt.Sprintf("declared by %s (from %s)", by, rule.From)
|
||||
}
|
||||
return "WILL CLOSE — no module assigned here declares it"
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user